Skip to main content

HIPAA Privacy Notice

How HelloDoc360 protects and handles your Protected Health Information under HIPAA.

Last Updated: July 12, 2026

Overview

This HIPAA Privacy Notice describes how HelloDoc360 ("we," "our," or "us") handles Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and its implementing regulations (45 CFR Parts 160 and 164), as amended by the HITECH Act.

HelloDoc360 operates as a healthcare provider directory and appointment scheduling platform. We function as a Business Associate to the healthcare providers listed on our platform and may create, receive, maintain, or transmit PHI on their behalf when facilitating appointment booking, secure messaging, and related services.

Protected Health Information We Handle

When you use our platform, we may handle the following categories of PHI:

  • Demographic information (name, date of birth, gender, contact details)
  • Insurance provider and policy numbers
  • Reason for visit and appointment preferences
  • Provider-patient messages sent through our secure messaging feature
  • Appointment history, scheduling details, and visit notes uploaded by patients
  • Medical records, lab results, or documents you choose to upload and share
How We Use and Disclose Your PHI

We use and disclose PHI only as permitted or required by HIPAA, including for:

  • Treatment: Facilitating appointment scheduling and secure communication between patients and providers.
  • Payment: Processing consultation fees and insurance-related information as directed by you or your provider.
  • Healthcare Operations: Maintaining the platform, verifying provider credentials, and improving our matching and booking services.
  • As Required by Law: Complying with legal obligations, court orders, or lawful government requests.
  • Public Health & Safety: Reporting to public health authorities, law enforcement, or to avert serious threats to health or safety, as permitted by HIPAA.

We will obtain your written authorization for any use or disclosure of PHI not described in this notice or otherwise permitted by HIPAA. You may revoke an authorization at any time in writing, except to the extent action has already been taken in reliance on it.

Safeguards for Your Information

We implement administrative, physical, and technical safeguards to protect PHI:

  • Administrative: Workforce training, access controls, and designated privacy and security oversight.
  • Physical: Secured facilities and restricted physical access to systems storing PHI.
  • Technical: Encryption in transit and at rest, unique user authentication, audit logging, and automatic session timeouts.
  • Business Associate Agreements: We execute BAAs with all subcontractors and vendors who may access PHI on our behalf.
Sharing With Healthcare Providers

When you book an appointment or send a message through HelloDoc360, the relevant PHI is shared with the healthcare provider you selected so they can deliver care. Each provider is an independent Covered Entity responsible for their own HIPAA compliance and Notice of Privacy Practices. We do not sell your PHI, and we do not use or disclose PHI for marketing without your authorization.

Your Rights Under HIPAA

You have the following rights regarding your PHI. To exercise any of these rights, contact us using the information at the bottom of this notice.

  • Access: Request to inspect and obtain a copy of your PHI.
  • Amendment: Request that we amend inaccurate or incomplete PHI.
  • Accounting of Disclosures: Request a list of certain disclosures we have made of your PHI.
  • Restrictions: Request restrictions on certain uses and disclosures of your PHI.
  • Confidential Communications: Request that we communicate with you in a specific manner or location.
  • Paper Copy: Request a paper copy of this notice at any time.
Breach Notification

In the event of a breach of unsecured PHI, we will notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, in accordance with the HIPAA Breach Notification Rule. Notifications will include a description of what happened, the types of information involved, steps you can take to protect yourself, what we are doing in response, and how to contact us for more information.

Changes to This Notice

We reserve the right to change the terms of this HIPAA Privacy Notice at any time. The updated notice will be posted on our website with a revised "Last Updated" date, and a copy will be available upon request. We will distribute a revised notice if we make material changes to our privacy practices.

Contact Us

If you have questions about this HIPAA Privacy Notice, wish to exercise any of your rights, or need to report a privacy concern, please contact us:

For our general data handling practices, please also review our Privacy Policy.